6 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. Cross-site scripting (XSS) reflejado en el repositorio de GitHub lirantal/daloradius antes de la rama maestra. • https://github.com/lirantal/daloradius/commit/e77a769c7503e63a2e3c05262cb5f8f81a4a7bbe https://huntr.dev/bounties/1c50a5a5-3f55-4b6f-b861-4d5cdb6eb81b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. Cross-site scripting (XSS) reflejado en el repositorio de GitHub lirantal/daloradius antes de la rama maestra. • https://github.com/lirantal/daloradius/commit/e77a769c7503e63a2e3c05262cb5f8f81a4a7bbe https://huntr.dev/bounties/fcae1b67-db37-4d24-9137-8dda95573e77 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. Restricción inadecuada de nombres de archivos y otros recursos en el repositorio de GitHub lirantal/daloradius antes de la rama maestra. • https://github.com/lirantal/daloradius/commit/2013c2d1231e99dac918247b69b198ded1f30a1c https://huntr.dev/bounties/2214dc41-f283-4342-95b1-34a2f4fea943 • CWE-641: Improper Restriction of Names for Files and Other Resources •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

Code Injection in GitHub repository lirantal/daloradius prior to master-branch. Inyección de código en el repositorio de GitHub lirantal/daloradius de la rama maestra. • https://github.com/lirantal/daloradius/commit/3650eea7277a5c278063214a5b71dbd7d77fc5aa https://huntr.dev/bounties/57abd666-4b9c-4f59-825d-1ec832153e79 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected in the DOM on line 116. This issue has been addressed in commit `ec3b4a419e`. Users are advised to manually apply the commit in order to mitigate this issue. Users may also mitigate this issue with in two parts 1) The CSRF vulnerability can be mitigated by making the daloRadius session cookie to samesite=Lax or by the implimentation of a CSRF token in all forms. 2) The XSS vulnerability may be mitigated by escaping it or by introducing a Content-Security policy. daloRADIUS es una aplicación de gestión web RADIUS de código abierto. daloRadius 1.3 y versiones anteriores son afectados por una vulnerabilidad combinada de Cross-Site Scripting (XSS) y Cross-Site Request Forgery (CSRF) que conduce a la apropiación de cuentas en el archivo mng-del.php debido a una variable sin escape reflejada en el DOM en line 116. Este problema se ha abordado en el commit "ec3b4a419e". • https://github.com/lirantal/daloradius/commit/ec3b4a419e20540cf28ce60e48998b893e3f1dea https://github.com/lirantal/daloradius/security/advisories/GHSA-c9xx-6mvw-9v84 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •